GPU VulnDB

Database/AI/ML frameworks & serving

Weaviate: Crafted entry name with an absolute path

CVSS 7.2CVE-2025-67818AI/ML frameworks & servingcurated

Impact

Crafted entry name with an absolute path → arbitrary file write

Who can reach it

Tenant with data-insert permission

What to do

Upgrade past 1.33.4; data insertion is a filesystem-write primitive

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.